PT-2020-19956 · Nextcloud+2 · Nextcloud Server+2
Published
2020-02-04
·
Updated
2020-10-15
·
CVE-2020-8119
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud server version 17.0.0
Description
The issue is related to improper authorization in the Nextcloud server, which causes previews and files to be leaked when a file-drop share link is opened via the gallery app.
Recommendations
For Nextcloud server version 17.0.0, update to a version that includes a fix for this issue to prevent unauthorized access to files and previews.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nextcloud Server
Suse